diff --git a/debian/fail2ban/firewall-ipset.conf b/debian/fail2ban/firewall-ipset.conf
new file mode 100644
index 0000000000000000000000000000000000000000..79af4dd951b208e47f7a5a5143fdb384b083a736
--- /dev/null
+++ b/debian/fail2ban/firewall-ipset.conf
@@ -0,0 +1,13 @@
+[Definition]
+
+actionban = ipset add <ipmset> <ip> timeout <ipsettime> -exist
+actionunban = ipset del <ipmset> <ip> -exist
+
+[Init]
+
+ipmset = f2b_ip
+ipsettime = 0
+
+[Init?family=inet6]
+
+ipmset = f2b_ip6
diff --git a/debian/firewall.install b/debian/firewall.install
new file mode 100644
index 0000000000000000000000000000000000000000..0dc77c40d5c7d9adae44c857b8e02e2e1bb2b714
--- /dev/null
+++ b/debian/firewall.install
@@ -0,0 +1 @@
+debian/fail2ban/firewall-ipset.conf etc/fail2ban/action.d